-
PCI: Maybe It’s Not Just For Card Data Any More
Posted on November 12th, 2009 No commentsWith all of the recent fuss about PCI requirements and how to protect payment cards, many companies have opted to take a far too narrow view of data protection. The PCI rules are absolutely designed to only apply to payment cards, but the same common-sense security guidelines will also dramatically help the security of CRM databases, personnel files, E-mail servers, payroll details, and even the full contents of your Web site.
-
PCI: Is Your Institution Compliant?
Posted on November 11th, 2009 No commentsRecent Assessments Find Flawed Security PracticesSince the Heartland data breach was announced in January, there’s been no shortage of discussion about the Payment Card Industry Data Security Standard(PCI DSS) and its requirements of merchants and payments processors. But what about financial institutions? Banks and credit unions store large amounts of cardholder data, but often show little awareness of PCI requirements, say security experts, including the Qualified Security Assessors (QSA) who test for PCI compliance.
Read more:
PCI: Is Your Institution Compliant? -
Drawing Security-Spooked Customers Into the E-Commerce Fold
Posted on November 11th, 2009 No commentsMany consumers are still afraid of shopping online, and it’s not hard to see why, with reports of fraud, identity theft, data loss and other security breaches regularly making the news. The fact is, though, online shopping is safer than ever before, and new and emerging security technologies, methods and standards are being implemented every day.
Read more from the original source:
Drawing Security-Spooked Customers Into the E-Commerce Fold -
Retail Data Breach Victim Rolls Back The Tech Clock
Posted on October 22nd, 2009 No commentsOne of the longstanding problems with retail security is that the best advice for retailers comes from experts in the field. And those people often work for the vendors that sell security products and services
Read the original post:
Retail Data Breach Victim Rolls Back The Tech Clock -
FCC and FTC Chairmen Jointly Encourage The Public to Take Safeguards to Protect Themselves, The Privacy, and Their Personal Information Online
Posted on October 9th, 2009 No commentsWashington, D.C. – As part of National Cyber Security Awareness Month, Federal Communications (FCC) Chairman Julius Genachowski and Federal Trade Commission (FTC) Chairman Jon Leibowitz today encouraged the public to take steps to protect themselves, their privacy, and their personal information online.
Read the original here:
FCC and FTC Chairmen Jointly Encourage The Public to Take Safeguards to Protect Themselves, The Privacy, and Their Personal Information Online -
Visa Releases Encryption Guidelines for Merchants
Posted on October 8th, 2009 No comments“Given the interest expressed by merchants and processors, guidance from the card brands is a critical determinant in figuring out how to move ahead with encrypting data in transit, especially absent a global standard,” said Avivah Litan, an analyst at Gartner, in a statement. “Companies should also be aware that if data is decrypted anywhere in their system, they are still at risk for a data breach.”
See the original post:
Visa Releases Encryption Guidelines for Merchants -
Visa Probes Tokens, Encryption for PCI Card Data Protection
Posted on October 8th, 2009 No commentsThe PCI Security Standards Council addressed emerging technologies at a meeting last month in Las Vegas and determined that encryption and tokenization were the top two emerging technologies deserving of attention.
See more here:
Visa Probes Tokens, Encryption for PCI Card Data Protection -
nCircle, Hitrust launch new security scanning service
Posted on October 6th, 2009 No commentsA new healthcare auditing program is designed to help smaller physician practices ensure that their electronic healthcare records are safe and secure. Developed by San Francisco-based nCircle and the Health Information Trust Alliance (HITRUST), the HITRUST Security and Configuration Auditing Service is designed to scan a provider’s IT systems for known vulnerabilities, identifying the highest risks in the network, and provide guidance on how to bring the systems up to date.
Read the original post:
nCircle, Hitrust launch new security scanning service -
UNC Latest College to Unveil Data Breach
Posted on October 5th, 2009 No commentsThe University of North Carolina at Chapel Hill this week began notifying the participants in a federally funded mammography study that their personal information may have been breached.
Go here to read the rest:
UNC Latest College to Unveil Data Breach -
Lawsuit: Heartland Knew Data Security Standard was ‘Insufficient’
Posted on October 5th, 2009 No commentsComplaint Says CEO Described PCI as ‘Lowest Common Denominator’ of ProtectionMonths before announcing the Heartland Payment Systems (HPY) data breach, company CEO Robert Carr told industry analysts that the Payment Card Industry Data Security Standard (PCI DSS) was an insufficient protective measure. This is the contention of a new master complaint filed in the class action suit against Heartland, which in January announced a data breach that is now estimated to be the largest known hack, involving 130 million credit and debt card accounts.
Originally posted here:
Lawsuit: Heartland Knew Data Security Standard was ‘Insufficient’



